CRITICAL

CVE-2024-55956

Cleo Harmony 2024-12-13 CVSS v3.1
CVSS
9.8
KEV

Description

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

Summary dbcve.org

Cleo Harmony, VLTrader, and LexiCom before version 5.8.0.24 contain a critical vulnerability allowing unauthenticated users to execute arbitrary Bash or PowerShell commands on the host system through the Autorun directory feature, which uses insecure default settings.

Mitigation

Upgrade to version 5.8.0.24 or later and review/restrict the Autorun directory configuration to prevent unauthorized command execution.

Proof of Concept

Weakness (CWE)

CWE-77 Command Injection

EPSS Score

93.97%
Probability of exploitation in next 30 days
99.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE